McEliece attack claim and Perl typemap CVEs
Security and cryptography traffic centered on a claimed quasipolynomial attack against Classic McEliece, with secondary notes on two niche Perl typemap CVEs and continued expert doubt over a lattice-breaking quantum algorithm claim. The McEliece thread dominated volume and temperature.
Claimed quasipolynomial attack on Classic McEliece
A new eprint asserts a quasipolynomial distinguisher and heuristic decryption against Classic McEliece. The pqc-forum thread ran to 112 messages from 16 participants and also contained a disclosure dispute involving Apon. Post-quantum cryptography implementers and standardizers have direct reason to track whether the claim holds under scrutiny.
Integer underflow in Perl STL List typemap
CVE-2026-107794 records that ExtUtils::Typemaps::STL::List versions before 1.07 allocate a 32 GiB array when given an empty list, caused by an integer underflow. The defect is corrected in 1.07. Maintainers of Perl XS code that binds STL lists should upgrade the module to prevent runaway memory use.
Skepticism on updated BQP lattice claim
Two messages on the NIST PQC list restate ongoing expert skepticism toward an updated eprint that claims a BQP algorithm breaks lattice cryptography. The exchange stays technical and limited in scope. Researchers evaluating quantum threats to lattice schemes will want the continued reservations on record.
Out-of-bounds read in Perl STL String typemap
CVE-2026-107373 notes that ExtUtils::Typemaps::STL::String versions before 1.06 may read SV length before stringifying the argument in the T_STD_STRING typemap, creating an out-of-bounds read risk. Version 1.06 addresses the issue. Users of this specialized XS typemap should move to the fixed release.